User Name Password Register
DaniWeb IT Discussion Community
All
What is DaniWeb IT Discussion Community?
You're currently browsing the Viruses, Spyware and other Nasties section within the Tech Talk category of DaniWeb, a massive community of 426,422 software developers, web developers, Internet marketers, and tech gurus who are all enthusiastic about making contacts, networking, and learning from each other. In fact, there are 2,389 IT professionals currently interacting right now! Registration is free, only takes a minute and lets you enjoy all of the interactive features of the site.
Please support our Viruses, Spyware and other Nasties advertiser: Programming Forums
Views: 3786 | Replies: 12
Reply
Join Date: Sep 2004
Posts: 5
Reputation: blondie074 is an unknown quantity at this point 
Rep Power: 0
Solved Threads: 0
blondie074 blondie074 is offline Offline
Newbie Poster

Help Home page gets directed to index page

  #1  
Sep 22nd, 2004
Help!!! I can't get to any websites on my IE. Everything keeps getting directed to this http:// 296f8.iltxt.info /index.php?aid=543 site, with a pop up saying that 18% of my files are corrupted with spyware. I need to be able to get to my email and other websites in a hurry for work........can anyone help me remove this virus?

Thanks!


Edit: Link has been altered so that it can't be accidentally clicked on. It leads to a nasty 'Web search' site which plays games with your brower. Don't go there please! - Catweazle
Last edited by Catweazle : Sep 23rd, 2004 at 6:03 am. Reason: Edit link to a hijack infested web page
AddThis Social Bookmark Button
Reply With Quote  
Join Date: Jun 2004
Location: Virginia
Posts: 253
Reputation: deonnanicole is an unknown quantity at this point 
Rep Power: 5
Solved Threads: 12
deonnanicole deonnanicole is offline Offline
Posting Whiz in Training

Re: HELP! Home page gets directed to index page

  #2  
Sep 22nd, 2004
If you haven't done so already, download Adaware and Spybot and scan your computer, rebooting between each, and let them fix anything they find. You can download them from here:

http://www.computercops.biz/zx/phoenix22/spybotsd13.zip
http://www.computercops.biz/downloads-file-292.html

After that, download and scan your computer with HijackThis. Be sure you update it to the latest version, which is 1.98.2. Scan your computer and post the log here. One of the security experts will take a look at it and advise you on fixing your computer. I don't have a link for HijackThis right offhand, but if you check in one of the other threads, more than likely there will be a link to it within a thread or in someone's sig. Good luck!
Reply With Quote  
Join Date: Jul 2004
Location: Washington, USA
Posts: 2,964
Reputation: dlh6213 is on a distinguished road 
Rep Power: 10
Solved Threads: 189
Colleague
dlh6213 dlh6213 is offline Offline
Posting Maven

Re: Home page gets directed to index page

  #3  
Sep 22nd, 2004
Here's a link for hijackthis:
http://www.softpedia.com/progDownloa...load-5034.html

"...I need to be able to get to my email and other websites in a hurry for work..."

You may need to find an alternate means of doing this as fixing your problem may take a few days.
Reply With Quote  
Join Date: Sep 2004
Posts: 5
Reputation: blondie074 is an unknown quantity at this point 
Rep Power: 0
Solved Threads: 0
blondie074 blondie074 is offline Offline
Newbie Poster

Re: Home page gets directed to index page

  #4  
Sep 22nd, 2004
OK, I scanned with adaware and spybot, and so here is the log from the HJT scan:

Logfile of HijackThis v1.98.2
Scan saved at 8:21:14 PM, on 9/22/2004
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\X5S9IMYIOYF3HN.EXE
C:\PROGRAM FILES\JUNO\EXEC.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\JUNO\EXEC.EXE
C:\PROGRAM FILES\JUNO\QSACC\X1EXEC.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowws.cc/hp.htm?id=543
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:7900
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 64.136.29.30;64.136.21.30;64.136.29.34;searchap.untd.com;127.0.0.1;localhost; *windowsupdate.microsoft.com;*windowsupdate.com;*wustat.windows.com; *profiles.yahoo.com;*.pogo.com;*test-speed.com;<local>
O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINDOWS\SYSTEM\7OSOSG~1.DLL
O4 - HKLM\..\RunOnce: [untd_recovery] C:\PROGRAM FILES\JUNO\QSACC\X1EXEC.EXE
O4 - HKCU\..\Run: [romahere2] C:\WINDOWS\SYSTEM\X5S9IMYIOYF3HN.EXE
O8 - Extra context menu item: Display Image with Full Quality - res://C:\PROGRAM FILES\JUNO\QSACC\appres.dll/227
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\PROGRAM FILES\JUNO\QSACC\appres.dll/228

Is there a name for this virus? I can't seem to figure out what it's called. What next?

Thanks for the speedy reply, by the way!

Heather
Reply With Quote  
Join Date: Jul 2004
Location: Washington, USA
Posts: 2,964
Reputation: dlh6213 is on a distinguished road 
Rep Power: 10
Solved Threads: 189
Colleague
dlh6213 dlh6213 is offline Offline
Posting Maven

Re: Home page gets directed to index page

  #5  
Sep 23rd, 2004
First, try these free online scans (set them to fix whatever they find):
http://housecall.trendmicro.com/
http://www.pandasoftware.com/actives..._principal.htm

Also, download CWShredder and run it. Select the fix button & it will fix everything related to CoolWebSearch that is stored in it's database. Close ALL windows before running CWShredder.
http://www.softpedia.com/progDownloa...load-8114.html

Reboot, scan with hjt and post a new log.
Reply With Quote  
Join Date: Jul 2004
Location: Washington, USA
Posts: 2,964
Reputation: dlh6213 is on a distinguished road 
Rep Power: 10
Solved Threads: 189
Colleague
dlh6213 dlh6213 is offline Offline
Posting Maven

Re: Home page gets directed to index page

  #6  
Sep 23rd, 2004
Before you post a new log, have hjt fix these entries:

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 64.136.29.30;64.136.21.30;64.136.29.34;searchap.untd.com;127.0.0.1;localhost; *windowsupdate.microsoft.com;*windowsupdate.com;*wustat.windows.com; *profiles.yahoo.com;*.pogo.com;*test-speed.com;<local>

O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINDOWS\SYSTEM\7OSOSG~1.DLL

O4 - HKCU\..\Run: [romahere2] C:\WINDOWS\SYSTEM\X5S9IMYIOYF3HN.EXE

Reboot into Safe Mode, go to the folder C:\WINDOWS\SYSTEM and delete this file:
X5S9IMYIOYF3HN.EXE

Reboot normally, scan with hjt, and now post a new log.
(Thank crunchie for this last bit, and thanks to Catweazle for editing the link in the original post.)
Reply With Quote  
Join Date: Sep 2004
Posts: 5
Reputation: blondie074 is an unknown quantity at this point 
Rep Power: 0
Solved Threads: 0
blondie074 blondie074 is offline Offline
Newbie Poster

Re: Home page gets directed to index page

  #7  
Sep 23rd, 2004
Hi, here is the new log after doing all that was asked of you guys.....except the panda scan....since it opens in a new window, the window flips back to the wierd index page I'm having problems with. Otherwise, everything else was done. Here's the log:

Logfile of HijackThis v1.98.2
Scan saved at 11:18:42 AM, on 9/23/2004
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\JUNO\EXEC.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\JUNO\EXEC.EXE
C:\PROGRAM FILES\JUNO\QSACC\X1EXEC.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
C:\UNZIPPED\HIJACKTHIS1.98.2\HIJACKTHIS.EXE

O4 - HKLM\..\RunOnce: [untd_recovery] C:\PROGRAM FILES\JUNO\QSACC\X1EXEC.EXE
O8 - Extra context menu item: Display Image with Full Quality - res://C:\PROGRAM FILES\JUNO\QSACC\appres.dll/227
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\PROGRAM FILES\JUNO\QSACC\appres.dll/228
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab

What next? Thanks for all your help here!!!!
Reply With Quote  
Join Date: Jul 2004
Location: Wales
Posts: 735
Reputation: DaveSW is on a distinguished road 
Rep Power: 6
Solved Threads: 17
DaveSW's Avatar
DaveSW DaveSW is offline Offline
Master Poster

Re: Home page gets directed to index page

  #8  
Sep 23rd, 2004
have you rebooted before posting that log? it looks kinda thin on the ground...
Reply With Quote  
Join Date: Sep 2004
Posts: 5
Reputation: blondie074 is an unknown quantity at this point 
Rep Power: 0
Solved Threads: 0
blondie074 blondie074 is offline Offline
Newbie Poster

Re: Home page gets directed to index page

  #9  
Sep 23rd, 2004
I thought I rebooted, but maybe not....I rebooted again and here is the log.

Logfile of HijackThis v1.98.2
Scan saved at 11:46:22 AM, on 9/23/2004
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\UNZIPPED\HIJACKTHIS1.98.2\HIJACKTHIS.EXE

O8 - Extra context menu item: Display Image with Full Quality - res://C:\PROGRAM FILES\JUNO\QSACC\appres.dll/227
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\PROGRAM FILES\JUNO\QSACC\appres.dll/228
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab

I also have noticed when I reboot, not everything loads (when I look at the task manager). I went into msconfig and notice it keeps defaulting to selective startup, rather than normal start up. I keep changing it back to normal, but it keeps defaulting to selective. Maybe that has something to do with the log not looking right. Is this a result of the virus?

Thanks!
Reply With Quote  
Join Date: Jul 2004
Location: Washington, USA
Posts: 2,964
Reputation: dlh6213 is on a distinguished road 
Rep Power: 10
Solved Threads: 189
Colleague
dlh6213 dlh6213 is offline Offline
Posting Maven

Re: Home page gets directed to index page

  #10  
Sep 25th, 2004
Originally Posted by blondie074
I also have noticed when I reboot, not everything loads (when I look at the task manager). I went into msconfig and notice it keeps defaulting to selective startup, rather than normal start up. I keep changing it back to normal, but it keeps defaulting to selective. Maybe that has something to do with the log not looking right. Is this a result of the virus?
Your log looks clean, I'm not sure how to fix your internet access problem. You could try installing SpywareBlaster, maybe it will block access to that site. You can download it from here:
http://www.javacoolsoftware.com/

Your startup problem certainly needs to be fixed, hopefully someone here can help you with that; I'm afraid I can't.
Reply With Quote  
Reply

Only community members can participate in forum threads. You must register or log in to contribute.

DaniWeb Viruses, Spyware and other Nasties Marketplace
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)

 

Thread Tools Display Modes

Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum

All times are GMT -4. The time now is 2:03 pm.
Forum system based on vBulletin Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
©2003 - 2008 DaniWeb® LLC